What is STACKIT Confidential Kubernetes?
STACKIT Confidential Kubernetes is a confidential computing platform that allows containerized applications to run in a cluster shielded from the underlying cloud infrastructure. It is built on Constellation, an open-source Kubernetes engine developed by Edgeless Systems, whose nodes run as Confidential Virtual Machines (CVMs) with hardware-based memory encryption. This keeps data protected even while it is being processed in memory and allows its integrity to be cryptographically verified.
Core Features
- Hardware-isolated cluster nodes based on Confidential Virtual Machines
- Transparent encryption of network and storage
- Remote attestation for individual nodes joining the cluster
- Proof of integrity for the entire cluster via a hardware-bound certificate
- Automated, transparent key management within the isolated environment
Typical Use Cases
Regulated industries: Healthcare, finance, and the public sector with strict data protection and auditability requirements.
Cloud migration of sensitive workloads: Organizations moving on-premises workloads with private-cloud-level security requirements into the public cloud.
Trustworthy SaaS offerings: Providers who want to cryptographically prove the isolation and integrity of their platform to customers.
Benefits
- Closes the gap between encryption at rest/in transit and encryption during processing
- Operated in German STACKIT data centers, GDPR compliant
- Verifiable security through remote attestation rather than pure trust in the provider
- Built on established open-source technology (Constellation)
Integration with innFactory
As an official STACKIT partner, innFactory supports the introduction of Confidential Kubernetes: from architecture and migration of existing workloads to ongoing operations and cost optimization.
Available Tiers & Options
Confidential
- Hardware-based isolation of cluster nodes
- Remote attestation for individual nodes and the whole cluster
- Encryption of storage and network
- Currently provided on a customer-specific basis, not full self-service
- Additional operational overhead compared to standard SKE
Typical Use Cases
Frequently Asked Questions
What is STACKIT Confidential Kubernetes?
A confidential computing platform that lets customers run containerized applications in a cluster shielded from the underlying cloud infrastructure at the hardware level. It is built on Constellation, an open-source Kubernetes engine by Edgeless Systems, running on Confidential Virtual Machines (CVMs).
How does the encryption work?
All Kubernetes nodes run inside encrypted CVMs. Network and storage are encrypted transparently, protecting data at rest, in transit, and while being processed in memory.
What does STACKIT Confidential Kubernetes cost?
The service is currently offered on a customer-specific basis; a concrete quote is obtained through STACKIT sales. The cost of the underlying Confidential Server is already included.
How can I verify the integrity of my cluster?
Each new node is verified via remote attestation before it is granted access to the cluster. The integrity of the entire cluster can additionally be proven using a hardware-bound certificate.
What use cases fit Confidential Kubernetes?
Regulated industries with strict compliance requirements, migrating sensitive workloads to the cloud, and providers who want to increase the trustworthiness of their SaaS offering through verifiable isolation.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of STACKIT (official documentation). This page does not represent an offer by STACKIT.
